News Article · Jun 27, 2026 at 8:41 AM
2 min read 0
Member
Fake OpenAI Tenants Target Cybersecurity Firms in 'Poisoned Tenant' Social Engineering Campaign
Security #phishing #social engineering #OpenAI #open source security #Polymarket #TinyRCT #APT

Fake OpenAI Tenants Target Cybersecurity Firms in 'Poisoned Tenant' Social Engineering Campaign

A wave of social engineering attacks using fraudulent OpenAI organizations is targeting cybersecurity firms. Employees receive legitimate-looking invites to fake corporate ChatGPT workspaces. Meanwhile, Polymarket confirms user fund theft, a new backdoor targets Southeast Asia, and a new initiative tackles end-of-life open source security.

Listen to this article 3 min

A sophisticated social engineering campaign dubbed 'Poisoned Tenant' is targeting employees at cybersecurity firms using fraudulent OpenAI organization invitations. Security vendor Push Security discovered the campaign after multiple employees received invites to join a fake ChatGPT workspace impersonating their own company.

The invitations came from OpenAI's legitimate notification email address and passed email authentication checks. Push Security told BleepingComputer that all known targets work in cybersecurity or technology.

Attacker Tactics: Research, CEO Impersonation, and Prepaid Accounts

Push Security researcher Luke Jennings accepted one invitation to investigate. He was immediately added to an organization impersonating Push Security and containing a single attacker-controlled account that used a Gmail address posing as the company's CEO, Adam Bateman. Invited employees were granted Owner privileges, giving them full administrative access to the tenant. The attackers had even attached a Visa credit card to the organization's billing account.

  • The attackers researched specific employees before sending invitations.
  • The fraudulent organizations contain no chats or projects, suggesting the goal is to collect submitted sensitive information over time.
  • Sensitive data at risk includes source code, internal documents, customer data, security research, and strategic plans.
  • Because invitations originate from OpenAI's own infrastructure, they bypass typical email security controls.
  • Push Security recommends employee training and monitoring of SaaS organization memberships.

Broader Cyber Landscape: Polymarket Breach, TinyRCT Backdoor, and Open Source Risks

In separate incidents, prediction market platform Polymarket confirmed user funds were stolen during a cyberattack. The company stated it is refunding affected users in full. The attack caused an estimated $3 million in losses for customers and is described as a supply-chain incident.

Meanwhile, Palo Alto Networks researchers identified a Chinese-speaking advanced persistent threat actor, tracked as CL-STA-1062, deploying a new custom backdoor called TinyRCT. The campaign targets government entities and state-owned enterprises in the energy and government sectors across Southeast Asia.

Amid these threats, the Open Source Sustainability Initiative launched with the goal of helping enterprises manage and secure aging open source projects. The initiative aims to address the growing risk of abandoned or end-of-life open source software while maintaining regulatory compliance.

Fact check

  • Push Security discovered the 'Poisoned Tenant' campaign targeting cybersecurity firms with fraudulent OpenAI organization invitations.

    verified · source

  • Polymarket confirmed user funds were stolen in a cyberattack and is refunding users in full.

    reported · source

  • A Chinese-speaking APT actor (CL-STA-1062) is deploying the TinyRCT backdoor against government and energy entities in Southeast Asia.

    reported · source

  • The Open Source Sustainability Initiative launched to help enterprises secure end-of-life open source software.

    reported · source

Source reporting (4)

0 Comments

No comments yet

Be the first to share your thoughts on this article.

Join the conversation

You need to be registered and logged in to comment on blog articles.

Who Is Online

In total there are 1021 users online: 0 registered, 1015 guests and 6 bots.

Most users ever online was 3,441 on 27 Jun 2026, 6:02 am.

Bots: AhrefsBot Applebot Baiduspider Googlebot Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 361